← All SwissSign AG certificates
Root Certificate

SwissSign Gold CA - G2

SwissSign AGCCADBCA Organization name as it appears in the CA's CP, CPS, CP/CPS and audit statements.
Browser Trust
Apple
AppleCCADBCertificate status in Apple: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Included
CCADB status only
Chrome
ChromeCCADBCertificate status in Google Chrome: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Removed
No direct match
Microsoft
MicrosoftCCADBCertificate status in Microsoft: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Included
Directly listed
Mozilla
MozillaCCADBCertificate status in Mozilla: for root certificates, this status indicates the certificates inclusion status with this program. for intermediate certificates, this will be Not Trusted if it is revoked, expired, or otherwise does not meet program-specific criteria. Otherwise set to Trusted.
Included
Directly listed
Trust Bit Detail
SourceTrust Bits
CCADB — Trust Bits for Root CertCCADBThis field is auto updated from a trigger in the CCADB that collects the union of Trust Bits configured by Root Store Operators.
  • Apple Trust Bits
  • Google Chrome Trust Bits
  • Microsoft EKUs For DTBs
  • Mozilla Trust Bits
Client AuthenticationSecure EmailServer Authentication
Microsoft — Inclusion ReportDirect sourceThe Microsoft EKUs field from Microsoft's own IncludedCACertificateReportForMSFTCSV report: the full list of EKUs Microsoft's program currently associates with this exact root, independent of CCADB's own trust-bit computation.
Client AuthenticationCode SigningSecure EmailServer Authentication
Microsoft — Confirmed EKUs (per-EKU report)Direct sourceBuilt by fetching Microsoft's IncludedRootsPEMCSVForMSFT report once per EKU value and checking whether this exact certificate's PEM appears in each. Verified against the actual certificate bytes rather than a self-reported EKU string.
Client AuthenticationCode SigningSecure EmailServer Authentication
MozillaDirect sourceThe Trust Bits field from Mozilla's own IncludedCACertificateReportCSVFormat report for this exact fingerprint. Can be narrower than CCADB's unioned Trust Bits, since it reflects only what Mozilla itself currently asserts.
Email
⚠ Apple publishes no direct machine-readable trust-bit source — only CCADB's own status is available for it.
Program Date Detail
SourceValid From [GMT]Valid To [GMT]
Microsoft — Direct ReportDirect sourceValidity dates parsed from Microsoft's own IncludedCACertificateReportForMSFTCSV report for this exact root certificate fingerprint. 2006-10-25 2036-10-25
Mozilla — Direct ReportDirect sourceValidity dates parsed from Mozilla's own IncludedCACertificateReportCSVFormat report for this exact root certificate fingerprint. 2006-10-25 2036-10-25
Root Program Precision
Cross-checked directly against each root program's own inclusion, per-EKU, and distrust-schedule reports — independent of CCADB's self-reported trust bit fields above.
Microsoft-confirmed EKUs (per-EKU report)Direct sourceBuilt by fetching Microsoft's IncludedRootsPEMCSVForMSFT report once per EKU value and checking whether this exact certificate's PEM appears in each. Verified against the actual certificate bytes rather than a self-reported EKU string.
Client AuthenticationCode SigningSecure EmailServer Authentication
Cross-program matrix: Apple Included · Chrome Removed · Microsoft Included · Mozilla Included
Certificate Details
Record TypeCCADBCCADB field: Certificate Record TypeOne of two values determined when certificate is added to the CCADB:
  • Intermediate Certificate
  • Root Certificate
Root Certificate
Subject DNComputed locallyThe certificate's own distinguished name, parsed from its PEM. This identifies who the certificate was issued to.
C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
Issuer DNComputed locallyThe distinguished name of the CA that signed this certificate, parsed from its PEM. This identifies who issued it.
C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
SHA-256CCADBCCADB field: SHA-256 FingerprintA SHA-256 hash of the certificate generated by the CCADB when adding a certificate PEM.
62DD0BE9B9F50A163EA0F8E75C053B1ECA57EA55C8688F647C6881F2C8357B95
Parent SHA-256CCADBCCADB field: Parent SHA-256 FingerprintA SHA-256 hash of the parent certificate, as generated by the CCADB when the parent certificate PEM was added.
Valid From (GMT)CCADBThe notBefore value extracted from the certificate PEM.
2006.10.25
Valid To (GMT)CCADBThe notAfter value extracted from the certificate PEM.
2036.10.25
AKICCADBCCADB field: Authority Key IdentifierThe authorityKeyIdentifier value extracted from the certificate PEM.
WyV7lqRlUX64OfPAeGZe6Drn8O4=
SKICCADBCCADB field: Subject Key IdentifierThe subjectKeyIdentifier value extracted from the certificate PEM.
WyV7lqRlUX64OfPAeGZe6Drn8O4=
Operated ByCCADBCCADB field: Subordinate CA OwnerThis is the subordinate CA Owner's name as it appears in the provided audit statements. CA Owners MUST NOT leave this field blank unless both control of the private key and domain/IP control validation activities are performed by the organization listed in the audit statement of the parent certificate.
ConstrainedCCADBCCADB field: Technically ConstrainedA boolean value configured by the CCADB when the certificate PEM was added. Set to FALSE if the certificate does not contain an Extended Key Usage (EKU) extension. Set to TRUE if the EKU does not contain id-kp-serverAuth or anyExtendedKeyUsage. If the EKU contains id-kp-serverAuth, then set to TRUE if the certificate includes the Name Constraints X.509v3 extension with constraints on dNSName, iPAddress and DirectoryName. Otherwise set to FALSE.
False
RevocationCCADBCCADB field: Revocation StatusOnly applicable to the Intermediate Certificate record type, the revocation status for this certificate as configured by the CA Owner.
  • –None–
  • Not Revoked
  • Revoked
  • Parent Cert Revoked
Salesforce IDCCADBCCADB field: Salesforce Record IDAn internal unique ID for this certificate in the CCADB. This value is assigned by the CCADB.
001o000000HshFuAAJ
Capabilities
EV OIDsCCADBCCADB field: EV OIDs for Root CertThis field is updated once daily by a batch program in the CCADB. It includes the union of all EV OIDs, as specified by Root Store Operators.
2.23.140.1.1; 2.16.756.1.89.1.2.1.1
Status of RootCCADBCCADB field: Status of Root CertRoot Store inclusion status for the root certificate that this intermediate certificate chains up to in the CCADB. (Updated via hourly batch process)
Apple
Included
Google Chrome
Removed
Microsoft
Included
Mozilla
Included
TLSCCADBCCADB field: TLS CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Server Authentication.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Server Authentication.
  • Otherwise set to FALSE.
TLS EVCCADBCCADB field: TLS EV CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Apple EV Enabled' is set to TRUE, or 'ExtendedValidation.cpp OIDs is not null, or 'Microsoft EV_SSL_Enabled is set to TRUE, or 'Google Chrome EV Enabled' is set to TRUE.
  • Set to TRUE for an intermediate certificate record if 'EV SSL Capable' is set to TRUE.
  • Otherwise set to FALSE.
Code SigningCCADBCCADB field: Code Signing CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Code Signing.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Code Signing.
  • Otherwise set to FALSE.
S/MIMECCADBCCADB field: S/MIME CapableA boolean value configured by the CCADB:
  • Set to TRUE for a root certificate record if 'Trust Bits For All Root Stores' contains Secure Email.
  • Set to TRUE for an intermediate certificate record if 'Derived Trust Bits' contains Secure Email.
  • Otherwise set to FALSE.
VMCCCADBCCADB field: VMC CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for Verified Mark Certificates.Document SigningCCADBCCADB field: Document Signing CapableNot documented as a separate field in the CCADB data dictionary. Computed by CCADB using the same Trust Bits / Derived Trust Bits mechanism as the other capability flags, for document signing EKU.
CAA IdentifiersCCADBCCADB field: AllCAAIdentifiersReportCSVV2A separate CCADB report, not part of the main certificate record (AllCertificateRecordsCSVFormatV5) used elsewhere on this page. CA Owners disclose the CAA issuer domain label(s) they use in DNS CAA records, tied to the specific intermediate certificate and Subject Key Identifier each declaration applies to.
Recognized CAA issuer identifiers published by CCADB for this CA certificate.
Not disclosed in CCADB
No recognized CAA issuer identifier was found for this CA certificate. CAs are expected to disclose CAA identifiers to CCADB when applicable.
Audit
Audit FirmCCADBCCADB field: AuditorA picklist value for the name of the Audit Firm that issued the audit statements, as selected by the CA Owner.
TÜV Austria
Firm LocationCCADBCCADB field: Audit Firm LocationNot documented as a separate field in the CCADB data dictionary. Disclosed alongside Auditor.
Austria
Same as ParentCCADBCCADB field: Audits Same as Parent?A boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if the current or next audit of the parent certificate includes this certificate. Otherwise set to FALSE, and all applicable audit fields must have values provided by the CA Owner.
false
Standard
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
ETSI EN 319 411
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2025.09.12
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2024.06.15 – 2025.06.13
TLS BR
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Baseline Requirements for the Issuance and Management of Publicly-Trusted TLS Server Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
ETSI EN 319 411
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2025.09.12
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2024.06.15 – 2025.06.13
TLS EVG
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Guidelines for the Issuance and Management of Extended Validation Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
ETSI EN 319 411
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2025.09.12
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2024.06.15 – 2025.06.13
S/MIME BR
Audit URLCCADBThe URL of the public attestation of conformance to the stated certificate verification requirements (CA/Browser Forum "Baseline Requirements for the Issuance and Management of Publicly-Trusted S/MIME Certificates") by the Qualified Auditor, as configured by the CA Owner.
TypeCCADBA picklist value for the type of audit scheme used, as selected by the CA Owner. In most cases this is either WebTrust or ETSI EN 319 411. In some cases this is an equivalent of either.
ETSI EN 319 411
StatementCCADBThe date the audit statement was issued by the Qualified Auditor, as configured by the CA Owner.
2025.09.12
PeriodCCADBThe start date and the end date for the period of time of CA operations examined by the Qualified Auditor.
2024.06.15 – 2025.06.13
Policy & Documentation
CP URLCCADBCCADB field: Certificate Policy (CP) URLThe URL to CP documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
CP Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certificate Policy (CP) information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
CP EffectiveCCADBCCADB field: CP Effective DateThe date the CP documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CP Same as Parent' is set to FALSE.
2026.07.10
CPS URLCCADBCCADB field: Certificate Practice Statement (CPS) URLThe URL to CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same Certification Practice Statement (CPS) information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
CPS EffectiveCCADBCCADB field: CPS Effective DateThe date the CPS documentation specific to this certificate became effective, as configured by the CA Owner. This value must be populated if 'CPS Same as Parent' is set to FALSE.
2026.03.13
CP/CPS StatementCCADBCCADB field: Certificate Practice & Policy StatementThe URL to the combined CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'CP/CPS Same as Parent' is set to FALSE.
CP/CPS Same as ParentCCADBA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
MD/AsciiDoc URLCCADBCCADB field: MD/AsciiDoc CP/CPS URLThe URL to the combined Markdown or AsciiDoc CP/CPS documentation specific to this certificate, as configured by the CA Owner. This value must be populated if 'MD/AsciiDoc CP/CPS Same as Parent' is set to FALSE.
MD/AsciiDoc Same as ParentCCADBCCADB field: MD/AsciiDoc CP/CPS Same as ParentA boolean value configured by the CA Owner for intermediate certificates: Set to TRUE if this certificate has the same combined Markdown or AsciiDoc CP/CPS information as the issuing certificate (or a subset). Otherwise set to FALSE.
false
Infrastructure
CRL (Full)CCADBCCADB field: JSON Array of All Full CRL URLsNot the exact documented field (the data dictionary describes an older single-URL "Full CRL Issued By This CA" field); this is its JSON-array successor in the current V5 report, holding the full CRL URL(s) for certificates issued by this CA, as configured by the CA Owner.
CRL (Parts)CCADBCCADB field: JSON Array of Partitioned CRLsWhen there is no full CRL for certificates issued by this CA, the CA Owner can provide a JSON array whose elements are URLs of partitioned, DER-encoded CRLs that when combined are the equivalent of a full CRL for certificates issued by this CA. The JSON array may omit obsolete partitioned CRLs whose scopes only include expired certificates.
ACME DVCCADBCCADB field: DV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Domain Validated issuance, as configured by the CA Owner.
ACME OVCCADBCCADB field: OV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Organization Validated issuance, as configured by the CA Owner.
ACME EVCCADBCCADB field: EV ACME Directory URL(s)Not documented as a separate field in the CCADB data dictionary. This CA's ACME directory URL(s) for Extended Validation issuance, as configured by the CA Owner.
Test (Valid)CCADBCCADB field: Test Website URL - ValidThe URL to a website with a valid TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Expired)CCADBCCADB field: Test Website URL - ExpiredThe URL to a website with an expired TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Test (Revoked)CCADBCCADB field: Test Website URL - RevokedThe URL to a website with a revoked TLS certificate that chains up to the root certificate, as configured by the CA Owner.
Policy OIDs
Certificate X.509 certificatePolicies
2.16.756.1.89.1.2.1.1
CCADB EV OIDs for Root Cert · administrative declaration
CA/B EV TLS2.23.140.1.12.16.756.1.89.1.2.1.1
Comparison
CCADB OID(s) not found in certificate: 2.23.140.1.1
Chain Validation
No parent certificate in CCADB — chain lint requires issuer
Certificate Lint (zlint, live)
pkimetal
Certificate (PEM)
crt.sh via Matador
By SPKI SHA-256 → All CT log entries sharing this public key, deduplicated — the broadest CT search for a CA
By SHA-256 → Look up this exact certificate by its fingerprint
By SKI → All certificates sharing this Subject Key Identifier
Issued Certificates → Resolve crt.sh issuer CA ID, then paginate all certificates issued by this CA
Mozilla OneCRL
StatusNameIssuerSerialBugModified
disabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00A96DDC39D36EBF15A4993FD028B476 1938770 2025-01-08
disabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 008108383CC00775C40C6D736BE3308B 1854222 2023-09-25
disabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00FA1DAAEAC9B3A5FA57980B9974DA31 1854222 2023-09-25
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00F792B7C4818C0458 2019-09-12
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 32C282C3A012007E 2019-09-12
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00B369A35C8438C22E4794CBC081223E 2019-09-12
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 272B67229745D2438BF9774186AEBD 2019-05-09
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00AF2D6F490B33B573CA699626C7C3DC 1521150 2019-03-13
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 0090EF71773BA96BF728BE53F0B653CE 1521150 2019-01-18
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 5EDC6C72FB236A09AC8C39AD86216D 1512640 2018-12-07
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 009584E2414091440359AFE94E01EADB 1512640 2018-12-07
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00843C74B1AA3486B1C4C7A0DF55B5E9 1420411 2017-11-24
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00843C74B1AA3486B1C4C7A0DF55B5E9 1420411 2017-11-24
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 49E1336E94E5B6A52DA96ED48AE276 1385914 2017-07-31
enabled C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2 00867A5AAFF875E150CF00BA36716950 1372586 2017-06-13

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action